s@lm@n
Microsoft
Exam 70-412
Configuring Advanced Windows Server 2012 R2 Services
Version: 26.0
[ Total Questions: 244 ]
http://certkill.com
Topic break down
Topic No. of Questions
Topic 1: Volume A 60
Topic 2: Volume B 60
Topic 3: Volume C 124
Microsoft 70-412 : Practice Test
2
http://certkill.com
Topic 1, Volume A
Your network contains an Active Directory domain named contoso.com. All file servers in
the domain run Windows Server 2012 R2.
The computer accounts of the file servers are in an organizational unit (OU) named OU1. A
Group Policy object (GPO) named GPO1 is linked to OU1.
You plan to modify the NTFS permissions for many folders on the file servers by using
central access policies.
You need to identify any users who will be denied access to resources that they can
currently access once the new permissions are implemented.
In which order should you Perform the five actions?
Answer:
Question No : 1 DRAG DROP - (Topic 1)
Microsoft 70-412 : Practice Test
3
http://certkill.com
âś‘
âś‘
Your network contains an Active Directory domain named contoso.com. The domain
contains domain controllers that run either Windows Server 2003, Windows Server 2008
R2, or Windows Server 2012 R2.
You plan to implement a new Active Directory forest. The new forest will be used for testing
and will be isolated from the production network.
In the test network, you deploy a server named Server1 that runs Windows Server 2012
R2.
You need to configure Server1 as a new domain controller in a new forest named
contoso.test.
The solution must meet the following requirements:
The functional level of the forest and of the domain must be the same as that of
contoso.com.
Server1 must provide name resolution services for contoso.test.
What should you do?
To answer, configure the appropriate options in the answer area.
Question No : 2 HOTSPOT - (Topic 1)
Microsoft 70-412 : Practice Test
4
http://certkill.com
Microsoft 70-412 : Practice Test
5
http://certkill.com
Answer:
Your company has a primary data center and a disaster recovery data center.
The network contains an Active Directory domain named contoso.com. The domain
contains a server named that runs Windows Server 2012 R2. Server1 is located in the
primary data center.
Server1 has an enterprise root certification authority (CA) for contoso.com.
You deploy another server named Server2 to the disaster recovery data center.
You plan to configure Server2 as a secondary certificate revocation list (CRL) distribution
point.
You need to configure Server2 as a CRL distribution point (CDP).
Question No : 3 HOTSPOT - (Topic 1)
Microsoft 70-412 : Practice Test
6
http://certkill.com
Which tab should you use to configure the required CDP entry? To answer, select the
appropriate tab in the answer area.
Answer:
Microsoft 70-412 : Practice Test
7
http://certkill.com
Your network contains an Active Directory domain named contoso.com. The domain
contains a domain controller named DC1 that runs Windows Server 2012 R2. DC1 has the
DNS Server server role installed.
The network contains client computers that run either Linux, Windows 7, or Windows 8.
Question No : 4 - (Topic 1)
Microsoft 70-412 : Practice Test
8
http://certkill.com
You have a standard primary zone named adatum.com as shown in the exhibit. (Click the
Exhibit button.)
You plan to configure Name Protection on all of the DHCP servers.
You need to configure the adatum.com zone to support Name Protection.
Which two configurations should you perform from DNS Manager? (Each correct answer
presents part of the solution. Choose two.)
A. Sign the zone.
B. Store the zone in Active Directory.
Microsoft 70-412 : Practice Test
9
http://certkill.com
C. Modify the Security settings of the zone.
D. Configure Dynamic updates.
E. Add a DNS key record
Answer: B,D
Explanation:
Name protection requires secure update to work. Without name protection DNS names
may be hijacked.
You can use the following procedures to allow only secure dynamic updates for a zone.
Secure dynamic update is supported only for Active Directory–integrated zones. If the zone
type is configured differently, you must change the zone type and directory-integrate the
zone before securing it for Domain Name System (DNS) dynamic updates.
1. (B) Convert primary DNS server to Active Directory integrated primary
2. (D) Enable secure dynamic updates
Microsoft 70-412 : Practice Test
10
http://certkill.com